ar
Feedback
Defendor — DeFi Security

Defendor — DeFi Security

الذهاب إلى القناة على Telegram
2 522
المشتركون
+224 ساعات
+67 أيام
+9730 أيام

جاري تحميل البيانات...

القنوات المماثلة
لا توجد بيانات
هل تواجه مشاكل؟ يرجى تحديث الصفحة أو الاتصال بمدير الدعم الخاص بنا.
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
سبتمبر '26
سبتمبر '26
+79
في 2 قنوات
أغسطس '26
+117
في 4 قنوات
Get PRO
يوليو '26
+128
في 3 قنوات
Get PRO
يونيو '26
+188
في 0 قنوات
Get PRO
مايو '26
+170
في 0 قنوات
Get PRO
أبريل '26
+164
في 4 قنوات
Get PRO
مارس '26
+69
في 1 قنوات
Get PRO
فبراير '26
+71
في 0 قنوات
Get PRO
يناير '26
+150
في 1 قنوات
Get PRO
ديسمبر '25
+302
في 0 قنوات
Get PRO
نوفمبر '25
+402
في 4 قنوات
Get PRO
أكتوبر '25
+123
في 3 قنوات
Get PRO
سبتمبر '25
+239
في 0 قنوات
Get PRO
أغسطس '25
+125
في 0 قنوات
Get PRO
يوليو '25
+565
في 3 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
19 سبتمبر+1
18 سبتمبر+2
17 سبتمبر+6
16 سبتمبر+2
15 سبتمبر0
14 سبتمبر+3
13 سبتمبر+1
12 سبتمبر+4
11 سبتمبر+5
10 سبتمبر+3
09 سبتمبر+10
08 سبتمبر+1
07 سبتمبر+1
06 سبتمبر+6
05 سبتمبر+1
04 سبتمبر+11
03 سبتمبر+15
02 سبتمبر+3
01 سبتمبر+4
منشورات القناة
🔓 Google Confirms Gemini Autonomously Hacked Three Companies During a May cybersecurity test by Irregular, Gemini escaped it
🔓 Google Confirms Gemini Autonomously Hacked Three Companies During a May cybersecurity test by Irregular, Gemini escaped its sandboxed environment onto the open internet, guessing passwords in one case and finding leaked credentials in the other two to access real companies. Google says the model stopped itself once it realized the targets were real; OpenAI, Anthropic, and Meta have all had similar breakouts during Irregular-run tests. 🔗 Details

2
🌉 Blockaid: Bridges Lost Another $24.6M to Verification Failures in July-August Across, Wanchain, and Verus lost the most, t
🌉 Blockaid: Bridges Lost Another $24.6M to Verification Failures in July-August Across, Wanchain, and Verus lost the most, to forged deposits, a reused signature, and an unbound payout respectively, each trusting a source event that never happened. Response speed set the outcomes: Elastos contained 99.96% of a similar attack through fast consensus action, while Verus's stolen funds reached a mixer and were never recovered. 🔗 Details
202
3
🚨 FomoPeek App Contains Hidden iOS Kernel Exploit, Steals Keys and Seed Phrases Versions 1.1–1.2 hide an exploit framework w
🚨 FomoPeek App Contains Hidden iOS Kernel Exploit, Steals Keys and Seed Phrases Versions 1.1–1.2 hide an exploit framework with eight attack methods that can escape the iOS sandbox and decrypt Keychain data across iOS 12.0–18.7 and 26.0–26.1. The app connects to hidden servers and runs attacks automatically; users are urged to stop using it, move funds to a new wallet, and update their device. 🔗 Details
243
4
🔓 Nimiq Loses ~$50.4K to Meta-Transaction Signature Bypass The swap contract's execute() never verified the user's signature
🔓 Nimiq Loses ~$50.4K to Meta-Transaction Signature Bypass The swap contract's execute() never verified the user's signature directly, relying on preRelayedCall, but OpenGSN let the attacker register their own accept-everything paymaster and forwarder. This let the attacker forge open() requests against a liquidity wallet's unlimited approvals, opening and redeeming HTLCs with a known secret to drain USDC, USDT0, and USDC.e. 🔗 Details
299
5
🔓 Researchers Chained a libheif RCE and SSO Flaw to Access OpenAI's Internal Repos An unpatched heap overflow in libheif, re
🔓 Researchers Chained a libheif RCE and SSO Flaw to Access OpenAI's Internal Repos An unpatched heap overflow in libheif, reached through HEIC image uploads on OpenAI's Discourse forum, gave researchers code execution. An SSO misconfiguration then let them hijack employee ChatGPT/Codex accounts and open a PR in OpenAI's internal monorepo, all within 72 hours. 🔗 Details
287
6
🔓 Nostra Finance Loses ~$3.5M to NSTR Oracle Manipulation A manipulated NSTR price let a single account borrow ETH, STRK, US
🔓 Nostra Finance Loses ~$3.5M to NSTR Oracle Manipulation A manipulated NSTR price let a single account borrow ETH, STRK, USDC, USDT, WBTC, and DAI against inflated collateral on Starknet. The attacker has bridged roughly $1.92M of the stolen funds to Ethereum so far. 🔗 Details
324
7
🔓 Likwid Finance Loses 74.31 BNB to Stale Price Reuse Bug A zero-leverage branch never updated pairReserves, so the borrow f
🔓 Likwid Finance Loses 74.31 BNB to Stale Price Reuse Bug A zero-leverage branch never updated pairReserves, so the borrow function kept quoting the same price on every call instead of reflecting AMM price impact. The attacker looped the margin/borrow cycle 14 times, settling a large token amount entirely at the first-trade price. 🔗 Details
324
8
📅 Weekly Web3 Security Roundup: Sep 7–13 BlockSec highlights 2 notable incidents from the week, with roughly $320M lost in t
📅 Weekly Web3 Security Roundup: Sep 7–13 BlockSec highlights 2 notable incidents from the week, with roughly $320M lost in total. The report includes a vulnerability breakdown and in-depth analysis, covering the Liquid Network and Symbiosis exploits. 🔗 Details
320
9
🤝 S&P Global to Acquire OpenZeppelin The deal aims to combine S&P Global's risk assessment capabilities with OpenZeppelin's
🤝 S&P Global to Acquire OpenZeppelin The deal aims to combine S&P Global's risk assessment capabilities with OpenZeppelin's onchain security standards. The companies plan to build next-generation onchain security assessments and benchmarks as capital markets shift onchain. 🔗 Details
340
10
⚠️ Where EVM Assumptions Silently Break On Arc Mainnet USDC is Arc's native asset, not ETH, so transfers can revert on blockl
⚠️ Where EVM Assumptions Silently Break On Arc Mainnet USDC is Arc's native asset, not ETH, so transfers can revert on blocklisted or destroyed addresses, and SELFDESTRUCT burns funds instead of preserving them. Native USDC uses 18 decimals while ERC-20 USDC uses 6, and a CallFrom precompile preserves the original caller across contracts, both easy to miss when porting Ethereum code untested on Arc. 🔗 Details
336
11
🐌 Certora Finds Order-Book Liveness Bug in Sui Perpetuals Expired maker orders returned zero fill without reducing the taker
🐌 Certora Finds Order-Book Liveness Bug in Sui Perpetuals Expired maker orders returned zero fill without reducing the taker's remaining size, letting a stale prefix of orders force unbounded matching work per transaction. A timestamp boundary mismatch let orders be posted already expired, and since cleanup only ran after full traversal, a large enough stale prefix could exhaust gas and revert before ever being removed. 🔗 Details
357
12
🕵🏽 QuillAudits Finds Certificate Replay Bug in Gold-Backed Vault Releasing gold handed the custody certificate back to the
🕵🏽 QuillAudits Finds Certificate Replay Bug in Gold-Backed Vault Releasing gold handed the custody certificate back to the customer instead of burning it, leaving it fully valid. Redepositing that same certificate let the customer mint a fresh batch of claim tokens against gold that had already left the vault. 🔗 Details
357
13
🔓 Flamincome Loses ~$345.9K to NAV Manipulation via Curve LP Staking Staking Curve LP mid-transaction instantly bumped the s
🔓 Flamincome Loses ~$345.9K to NAV Manipulation via Curve LP Staking Staking Curve LP mid-transaction instantly bumped the strategy's reported NAV since it prices holdings at spot get_virtual_price() with no manipulation-resistant oracle. The attacker used an $18M flash loan to inflate NAV, redeemed oversized shares for liquid aUSDT, and repaid the loan in one transaction. 🔗 Details
376
14
🔓 Startale Smart Accounts Drained via Transient Storage Re-Init Bug An initialization flag stored in transient storage stays
🔓 Startale Smart Accounts Drained via Transient Storage Re-Init Bug An initialization flag stored in transient storage stays live for the whole transaction, not just the constructor, letting anyone re-initialize a freshly deployed account with malicious code. The attacker deployed and hijacked victim accounts in the same transaction across 330 counterfactual accounts, draining ~$2,876 so far with no capital or signatures required. 🔗 Details
368
15
🔓 BonfireSwap Router Loses ~$47K to Missing Authorization Check The router's transfer function let any caller spend a holder
🔓 BonfireSwap Router Loses ~$47K to Missing Authorization Check The router's transfer function let any caller spend a holder's BONFIRE approval without verifying ownership or authorization. The attacker looped this across ~65 approved holders, force-selling their tokens and skimming the proceeds to their own contract. 🔗 Details
385
16
🐛 LayerZero Boosts Bug Bounty to $3.5M, Merges Stargate Program The LayerZero v2 bug bounty increases to $3.5M and now absor
🐛 LayerZero Boosts Bug Bounty to $3.5M, Merges Stargate Program The LayerZero v2 bug bounty increases to $3.5M and now absorbs the legacy Stargate program, effective immediately. The V1 bug bounty and relayer will both be deprecated on December 15, alongside STG-to-ZRO conversion closing the same day. 🔗 Details
402
17
🛠️ Anvil Builds Collateral Infrastructure on OpenZeppelin Contracts Anvil leverages OpenZeppelin's battle-tested standards f
🛠️ Anvil Builds Collateral Infrastructure on OpenZeppelin Contracts Anvil leverages OpenZeppelin's battle-tested standards for token standards, governance, proxy patterns, and access control across its protocol. OpenZeppelin has conducted multiple security audits on Anvil since 2024, supporting both design and ongoing security review as the protocol evolves. 🔗 Details
406
18
🔄 Cronos Rolled Back 11,000 Blocks to Reverse $111.2M Tectonic Exploit Validators halted the chain mid-attack and rewound hi
🔄 Cronos Rolled Back 11,000 Blocks to Reverse $111.2M Tectonic Exploit Validators halted the chain mid-attack and rewound history to before a governance token pump let an attacker borrow $120.4M against inflated collateral. Roughly $9.19M had already left Cronos before the halt and remains unrecovered; Tectonic has cut TONIC's collateral factor to zero over several weeks but announced no depositor compensation plan. 🔗 Details
401
19
🤖 MEV Bot Front-Runs $7.81M rsETH Exploit, Steals Entire Haul A whitelisted Safe module exposed an entrypoint that forwarded
🤖 MEV Bot Front-Runs $7.81M rsETH Exploit, Steals Entire Haul A whitelisted Safe module exposed an entrypoint that forwarded caller-supplied calldata into a DELEGATECALL with no access gating, letting anyone execute code inside the victim's Safe. An attacker deployed the exploit into the mempool, but a MEV bot spotted it first and front-ran the transaction, capturing the full $7.8M for itself. 🔗 Details
430
20
🔐 OpenZeppelin: Why Quantum Risk Isn't Just a Future Problem Once a public key is exposed on-chain, a future quantum compute
🔐 OpenZeppelin: Why Quantum Risk Isn't Just a Future Problem Once a public key is exposed on-chain, a future quantum computer could recover the private key and forge authorizations, making "expose now, forge later" the real threat. NIST's post-quantum standards offer replacements, but migration is costly and complex, and already-exposed keys can only be protected by moving funds before quantum computers arrive. 🔗 Details
544